Senior Performance Engineer - Fulltime (Toronto)

Senior Performance Engineer - Fulltime (Toronto)

03 Oct
|
OpenLoop Health
|
Toronto

03 Oct

OpenLoop Health

Toronto

Jon Lensing, and COO, Christian Williams, with the vision to bring care anywhere. Our telehealth support solutions are thoughtfully designed to streamline and simplify go-to-market care delivery for companies offering meaningful virtual support to patients across an expansive array of specialties, in all 50 states. Staff IAM Architect to be the design authority for identity across the company: workforce, non-employee, customer, partner, non-human, and AI agent.

Service accounts and AI agents are on track to outnumber the people we govern, and very few companies have a real architecture for them yet. Auth0 is our customer identity platform, procured with machine-to-machine flows in production and the interactive login experience in active build. iam-ops-hub, our identity posture and remediation platform, is built in house and deployed. What we do not have is a single design authority tying them together.

Architecture currently gets decided project by project, under delivery pressure. This is a hands-on architecture role, and we mean that concretely. Expect to write Auth0 Actions, Okta Workflows, and Terraform, and to query the posture warehouse yourself.

Own the target-state identity architecture across workforce, non-employee, external, non-human, and AI agent identity types, and set the standards, reference patterns, and decision records that make platform choices consistent rather than improvised per project. Own our Auth0 customer identity architecture end to end, including tenant and organization modelling, MFA and phishing-resistant authentication, and machine-to-machine patterns, taking it from partially live to fully architected and governed across our external and partner use cases.



Keep the customer and patient identity plane deliberately separate from the workforce plane, define the interfaces where the two must meet, and design the external and partner identity models for third‑party developers and B2B customers.

Design SSO, SCIM provisioning, and automated deprovisioning patterns for applications handling sensitive data, with audit evidence produced as a byproduct of the design rather than as a manual exercise. Define the federation and directory architecture across Okta, Entra ID, AWS, and GCP, including subsidiary and acquisition integration patterns. Build out Identity Security Posture Management, extending the posture warehouse and remediation engine we built in house, and define the metrics that tell us whether identity posture is actually improving.

Design access controls that satisfy HIPAA, HITRUST, and SOC 2 requirements without adding manual overhead, and keep architecture documentation and control mappings current enough that supporting an audit is a lookup rather than a project. Serve as the design authority between the function that surfaces identity risk and the function that builds, so that every finding has a clear architectural path to remediation. You would rather write the reference implementation than describe it.

You document decisions so they survive your absence, and you would rather be disagreed with in writing than agreed with in a hallway.



Comfortable owning direction without owning headcount, and effective at getting engineering teams to adopt your patterns because they are good, not because you outrank anyone. 8+ years in identity and access management, security engineering, or platform architecture, with at least 3 years at a staff, principal, or architect level. ~ Deep, hands‑on customer identity experience. Demonstrated ability to set architectural direction and get engineering teams to adopt it without direct authority. ~ Cloud‑native identity across AWS, GCP, and Azure, including migrations off cloud‑provider user pools such as AWS Cognito, or off social and directory sign‑in such as Google Sign‑In.

Building Identity Security Posture

Management or identity threat detection capability, including SIEM integration for identity telemetry. Non‑human identity, service account governance, secrets management, or AI agent identity. HITRUST, SOC 2, or SOX access controls.

Digital health, telehealth, or another regulated high‑growth environment. A target‑state identity architecture approved, published, and adopted, with decision records for every material choice. Our customer identity architecture complete, and the interactive login plane delivered to production across external and partner use cases.

A published consolidation architecture that engineering builds against, with measurable movement of our application portfolio onto a single workforce IdP. Audit evidence produced as a byproduct of design, with control mappings traceable directly to architecture documents. Medical, Dental, and Vision plans ~ Flexible Spending/Health Savings Accounts ~ Versatile PTO ~Life Insurance, Pet insurance, and more

📌 Senior Performance Engineer - Fulltime (Toronto)
🏢 OpenLoop Health
📍 Toronto

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: senior performance engineer - fulltime (toronto) / toronto